Skip to main content

Okta confirms another breach after hackers steal source code

Identity and authentication company Okta has revealed that it is dealing with another significant security incident after a hacker accessed its source code following a breach of its GitHub repositories. The company said in a statement that it had received notification from GitHub about “suspicious access” to its code repositories earlier this month, and that the hackers had used this access to copy code repositories related to Workforce Identity Cloud (WIC), its enterprise security solution. Okta added that there had been no unauthorized access to its service or customer data, and that products related to Auth0, which it acquired in 2021, were not impacted. Okta did not disclose how the hackers had gained access to its private repositories.

According to a confidential email notification sent by Okta internally and seen by BleepingComputer, GitHub notified the San Francisco-based company of suspicious activity in its code repositories in December 2022.

Okta’s internal email and public advisoryOpens a new window says unknown threat actors copied some GitHub repositories containing source code but clarified that no customer data or company infrastructure was impacted. The incident was reportedly limited to Okta Workforce Identity Cloud repositories.

Okta added that as soon as it learned of the possible suspicious access, it promptly placed temporary restrictions on access to its GitHub repositories and suspended all GitHub integrations with third-party applications. The company also stated that there had been no unauthorized access to its service or customer data, and that products related to Auth0, which it acquired in 2021, were not impacted. Okta did not disclose how the hackers had gained access to its private repositories.

This is not the first time that Okta has faced such a threat. Earlier this year, the company was targeted by the Lapsus$ extortion group, which gained access to the account of a customer support engineer at one of Okta’s third-party service providers, Sykes, and posted screenshots of Okta’s apps and systems. In August of this year, Okta faced another compromise when it was targeted by a hacking campaign that affected more than 100 organizations, including Twilio and DoorDash.

Popular posts from this blog

AT&T Resets Millions of Customer Passcodes After Data Leak: What You Need to Know

AT&T recently confirmed a significant data breach affecting over 7.6 million current customers and 65 million former customers. The leaked information, which dates back to 2019 or earlier, includes personal details like names, addresses, phone numbers, and social security numbers. Fortunately, financial information and call history were not compromised. In response to the breach, AT&T has reset passcodes for affected customers. Passcodes, usually four-digit numbers, serve as an additional layer of security when accessing accounts. However, security experts warn that the encrypted passcodes leaked alongside customer information could be easily deciphered, posing a risk of unauthorized account access. Affected customers are advised to set up free fraud alerts with major credit bureaus and remain vigilant for any suspicious activity related to their accounts. AT&T is proactively reaching out to impacted customers via email or letter to inform them about the breach and the meas...

Sam Bankman-Fried sentenced to 25 years in jail for FTX fraud

FTX co-founder Sam Bankman-Fried has been sentenced to 25 years in prison for his involvement in seven counts of conspiracy and fraud related to the collapse of the cryptocurrency exchange he established. The judge handed down a sentence of 240 months for four charges and 60 months for two others, along with ordering Bankman-Fried to forfeit more than $11 billion, including property, as recommended by prosecutors. The judge's decision fell short of the 40 to 50 years requested by prosecutors, but exceeded the defense's plea for six and a half years, though it was notably less than the maximum sentence of 110 years. During the trial, it was revealed that Bankman-Fried was aware of the risks FTX faced, misused customer funds, and knowingly engaged in wrongful activities. He justified his actions by weighing the risk of getting caught against potential gains. The judge dismissed claims that customers would be reimbursed, highlighting that FTX customers suffered losses of $8 billio...

What is a VPN and why would you need one?

  Understanding VPN: A Comprehensive Guide for Beginners In today's digital age, the internet is an essential part of our daily lives. From online banking and shopping to social networking and entertainment, we rely on the internet for numerous activities. However, with the increasing reliance on the internet, concerns about online privacy and security have become more prominent. This is where a VPN comes into play. If you're unfamiliar with the term, this guide will explain what a VPN is, how it works, and why you might want to consider using one. What is a VPN? VPN stands for Virtual Private Network. It is a service that creates a secure, encrypted connection between your device (such as a computer, smartphone, or tablet) and the internet. Think of it as a private tunnel through which your data travels, hidden from prying eyes. How Does a VPN Work? When you connect to the internet without a VPN, your data travels through your Internet Service Provider (ISP) and can be potenti...